EnternicaBack to sign up

Privacy · Pre-release draft

Privacy Policy

A transparent account of the personal data the current Enternica product processes—and the decisions still required before launch.

Last reviewed: 9 October 2026

Pre-release review status

This draft describes the product as it exists today. It is not legally approved and must not be used for public launch until the operator identity, official contact channel, retention schedule, and remaining legal terms are approved.

Placeholder values

Launch details awaiting approval

Legal operator
Pending founder confirmation
Registered address
Pending founder confirmation
Privacy and legal contact
Pending founder confirmation
Effective date
Not yet effective

On this page

  1. Scope and current status
  2. Data the product processes
  3. Where data comes from
  4. Purposes and lawful bases
  5. Visibility and sharing
  6. International data transfers
  7. Cookies and local storage
  8. Retention and deletion
  9. Security
  10. Your privacy rights
  11. Children and protected users
  12. Data incidents
  13. Contact and policy changes

01

Scope and current status

This notice describes personal-data processing visible in the current Enternica product and repository. It is designed around Indonesia'sLaw No. 27 of 2022 on Personal Data Protection and Government Regulation No. 71 of 2019 on Electronic Systems and Transactions.

The identity and address of the production data controller have not yet been approved for publication. That information and a working privacy-rights contact are mandatory launch blockers.

02

Data the product processes

Depending on how you use Enternica, the product can process:

  • Account data: name, email, authentication provider, password credentials managed by the authentication provider, phone contact, verification state, and session records.
  • Professional data: profile details, role, services, public media, official links, representation, and authority records.
  • Inquiry and event data: event requirements, schedule, location, messages, availability, and proposal history.
  • Booking and agreement data: accepted terms, revisions, designations, consent evidence, signatures, generated documents, delivery records, and completion state.
  • Finance records: invoices, bank-transfer destination snapshots, payment evidence, review state, and related references. The current product does not store card credentials.
  • Technical data: necessary cookies, identifiers, request and security information, and records needed to prevent unauthorized access and diagnose service failures.

03

Where data comes from

Data comes from you, other authorized participants in a shared booking or professional workspace, your chosen sign-in provider, and technical records created when the product operates. Users must not submit another person's data without authority and an appropriate lawful basis.

04

Purposes and lawful bases

Enternica processes data to:

  • create and secure accounts and verify trusted identities;
  • provide profiles, inquiries, bookings, agreements, and invoices;
  • deliver files and records to authorized participants;
  • prevent fraud, abuse, unauthorized access, and data loss;
  • diagnose failures and maintain product integrity; and
  • meet applicable contractual and legal obligations.

The intended bases include steps requested before a contract, performance of a contract, compliance with legal obligations, explicit consent where required, and proportionate legitimate interests balanced against user rights. Each production purpose must be mapped to its final basis before launch.

05

Visibility and sharing

Published professional profiles and selected media are public. Private inquiries, bookings, agreements, invoices, payment evidence, contact data, and authority records are intended only for authenticated users with the required relationship or authority.

Data can be processed by infrastructure providers needed to operate the service. The current implementation uses Supabase for authentication and database services, Cloudinary for configured media and restricted-document delivery, and Google when a user chooses Google sign-in. Final production email and hosting providers remain to be approved and must be added to this notice.

06

International data transfers

External infrastructure providers may process data outside Indonesia. Production regions, transfer recipients, and applicable safeguards have not yet been confirmed. Enternica must document and validate an appropriate transfer basis before hosted public deployment.

07

Cookies and local storage

The current product uses necessary cookies for authenticated sessions, provisional verification, safe return paths, and active workspace context. These are required for security and core product operation. The audited application does not currently implement advertising or behavioral-marketing cookies. Any future non-essential tracking must be separately disclosed and, where required, consented to before use.

08

Retention and deletion

Data should be retained only while needed for the stated purpose, security, contractual records, dispute handling, or a legal retention obligation, then deleted or anonymized where appropriate.

The product does not yet expose a complete retention schedule, self-service export, or account-deletion workflow. Exact periods for accounts, inquiries, agreements, financial records, security logs, backups, and uploaded files must be approved and published before launch.

09

Security

The current implementation uses role and relationship checks, least-privilege database policies, restricted delivery links, verified authentication states, and security-focused regression tests. No system is perfectly secure. Production incident response, monitoring, backups, and restore evidence remain separate launch requirements.

10

Your privacy rights

Subject to applicable law and identity verification, individuals can have rights to information, access, correction, a copy or transfer of their data, withdrawal of consent, restriction or objection, termination of processing, deletion, and complaint or compensation. Some requests can be limited where another person's rights, security, active disputes, contracts, or legal retention duties apply.

A recorded electronic or non-electronic request channel and response procedure must be approved before public launch. The product must not imply that an unavailable self-service control has already fulfilled a legal request.

11

Children and protected users

Enternica is not currently designed as a service for children. The minimum user-age rule, parental or guardian authorization process, and any handling of data about child performers require a specific founder and legal decision before such use is permitted.

12

Data incidents

If a personal-data protection failure occurs, the production operator must investigate, contain, document, and provide notices required by applicable law. Indonesian Law No. 27 of 2022 includes a written notice deadline of no later than 3 × 24 hours for qualifying failures. A tested production incident-response owner and contact path remain launch requirements.

13

Contact and policy changes

A verified privacy contact, operator legal name, registered address, and escalation route must be published here before this notice becomes effective. No address is fabricated in this pre-release draft.

Material changes should identify their effective date and be communicated appropriately. A new purpose or processor must be assessed and documented before related processing starts.

Enternica pre-release legal review

Terms of ServicePrivacy Policy